# Archetype Designer connecting to Ontoserver with login via Azure Active Directory?

**URL:** https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109
**Category:** Archetype Designer
**Tags:** snomed-ct, ontoserver
**Created:** [13 June 2023 07:53 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109 "2023-06-13T07:53:20Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![Paulmiller](https://discourse.openehr.org/user_avatar/discourse.openehr.org/paulmiller/32/2733_2.png) [@Paulmiller](https://discourse.openehr.org/u/Paulmiller)
#### Post date: [13 June 2023 07:53 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109/1 "2023-06-13T07:53:20Z")

</div>

Hi all

I am trying to configure Archetype Designer to use NHS Scotland’s Ontoserver.

I can set this up using the settings:

 ![image](https://discourse.openehr.org/uploads/default/original/2X/9/96f6557a17036525f865a16d09c78cf18a495688.png)

but access is limited, e.g. you cannot see SNOMED CT code system, which is not a great help.

To access the full production server via the web I log into the server using my AAD login, but there is no way to pass or enter this login in Archetype Designer to let me access the full resources.

I suspect this is not a fixable problem right now, which in turn is something of a blocker for me doing useful work.

Unless any of you know different?

Thanks

---

<div class="post-metadata">

### Author: ![ian.mcnicoll](https://discourse.openehr.org/user_avatar/discourse.openehr.org/ian.mcnicoll/32/4430_2.png) [@ian.mcnicoll](https://discourse.openehr.org/u/ian.mcnicoll)
#### Post date: [13 June 2023 08:27 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109/2 "2023-06-13T08:27:03Z")

</div>

Just add a /

[https://ontology.scot.nhs.uk/production1/fhir/](https://ontology.scot.nhs.uk/production1/fhir/)

 ![image](https://discourse.openehr.org/uploads/default/original/2X/a/a265601dd66bd93b3123438d18b08789b38af94b.png)

---

<div class="post-metadata">

### Author: ![Paulmiller](https://discourse.openehr.org/user_avatar/discourse.openehr.org/paulmiller/32/2733_2.png) [@Paulmiller](https://discourse.openehr.org/u/Paulmiller)
#### Post date: [13 June 2023 10:13 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109/3 "2023-06-13T10:13:26Z")

</div>

Thanks Ian, I don’t think this fixes it.

Talking to the Ontoserver people it seems there is an authentication layer implemented to secure access to SNOMED content. This is maybe a design decision, to comply with the license, but equally may not be needed. I will explore further.

Otherwise Archetype Designer does not have a way to enter authentication credentials for the terminology server.

So, am a bit stuck right now ☹

---

<div class="post-metadata">

### Author: ![ian.mcnicoll](https://discourse.openehr.org/user_avatar/discourse.openehr.org/ian.mcnicoll/32/4430_2.png) [@ian.mcnicoll](https://discourse.openehr.org/u/ian.mcnicoll)
#### Post date: [13 June 2023 10:42 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109/4 "2023-06-13T10:42:55Z")

</div>

Yes - I’ve come across this before . I’ll raise it with @borut.fabjan

---

<div class="post-metadata">

### Author: ![ian.mcnicoll](https://discourse.openehr.org/user_avatar/discourse.openehr.org/ian.mcnicoll/32/4430_2.png) [@ian.mcnicoll](https://discourse.openehr.org/u/ian.mcnicoll)
#### Post date: [13 June 2023 12:46 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109/5 "2023-06-13T12:46:32Z")

</div>

I have raised a CR re Archetype Designer but I suspect it might be quite tricky to support the more complex forms of authentication and it would be much better if auth was not needed for read-only access.

---

<div class="post-metadata">

### Author: ![Paulmiller](https://discourse.openehr.org/user_avatar/discourse.openehr.org/paulmiller/32/2733_2.png) [@Paulmiller](https://discourse.openehr.org/u/Paulmiller)
#### Post date: [13 June 2023 15:10 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109/6 "2023-06-13T15:10:19Z")

</div>

Yes, I agree. I will make that suggestion when I raise a support ticket with out Ontoserver team.

---

<div class="post-metadata">

### Author: ![borut.fabjan](https://discourse.openehr.org/letter_avatar_proxy/v4/letter/b/d78d45/32.png) [@borut.fabjan](https://discourse.openehr.org/u/borut.fabjan)
#### Post date: [21 August 2023 13:17 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109/7 "2023-08-21T13:17:52Z")

</div>

It’s a bit of a design decision.  
For a SaaS service, you probably don’t want users to store 3rd party service credentials within AD 😉

---

<div class="post-metadata">

### Author: ![Marcvanaalten](https://discourse.openehr.org/user_avatar/discourse.openehr.org/marcvanaalten/32/3583_2.png) [@Marcvanaalten](https://discourse.openehr.org/u/Marcvanaalten)
#### Post date: [6 August 2025 14:35 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109/8 "2025-08-06T14:35:17Z")

</div>

@Paulmiller I want to connect to the Dutch National Terminology Server. It is a Ontoserver instance that contains all the terminologies, ValueSets and CodeSystems. But I can’t find this configuration screen. Is it still possible in the Archetype Designer?

---

<div class="post-metadata">

### Author: ![ian.mcnicoll](https://discourse.openehr.org/user_avatar/discourse.openehr.org/ian.mcnicoll/32/4430_2.png) [@ian.mcnicoll](https://discourse.openehr.org/u/ian.mcnicoll)
#### Post date: [6 August 2025 14:57 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109/9 "2025-08-06T14:57:20Z")

</div>

![CleanShot 2025-08-06 at 15.55.33](https://discourse.openehr.org/uploads/default/original/2X/6/68fd3b0dbc3a95fce991691cc469f072c45bd4e7.png)

Click on the Account icon Top-left then Settings. You may have issues connecting if Ontoserver instance is not open, as AD does not allow aith credntials to be passed through.

---

<div class="post-metadata">

### Author: ![Paulmiller](https://discourse.openehr.org/user_avatar/discourse.openehr.org/paulmiller/32/2733_2.png) [@Paulmiller](https://discourse.openehr.org/u/Paulmiller)
#### Post date: [13 August 2025 11:15 UTC](https://discourse.openehr.org/t/archetype-designer-connecting-to-ontoserver-with-login-via-azure-active-directory/4109/10 "2025-08-13T11:15:47Z")

</div>

We arranged to set up a “secret” proxy server for use by known users only to allow AD to access the Ontoserver SNOMED content. This works ok, though I have not had much opportunity to use it for practical purposes as yet

Paul
